Mozi Malware - Finding Breadcrumbs...

2021 ж. 28 Ақп.
197 115 Рет қаралды

If you would like to support the channel and I, check out Kite! Kite is a coding assistant that helps you code faster, on any IDE offer smart completions and documentation. www.kite.com/get-kite/?... (disclaimer, affiliate link)
For more content, subscribe on Twitch! / johnhammond010
If you would like to support me, please like, comment & subscribe, and check me out on Patreon: / johnhammond010
PayPal: paypal.me/johnhammond010
E-mail: johnhammond010@gmail.com
Discord: johnhammond.org/discord
Twitter: / _johnhammond
GitHub: github.com/JohnHammond

Пікірлер
  • Dragging the spooky.elf into GHIDRA, it opens it just fine, and I should have tried that during the video. Embarrassing mistake, sorry. (And yes, I know that is by Fall Out Boy, not Green Day. I was just trolling ;P )

    @_JohnHammond@_JohnHammond3 жыл бұрын
    • No worries :)

      @originalgaming9062@originalgaming90623 жыл бұрын
    • @John Hammond this is a worm used to infect routers so they can monitor router data and etc

      @dannygaming1216@dannygaming12163 жыл бұрын
    • the default passwords may be for routers, people often forget to change them. there are sites that if you look up a router you can get a list of default passwords

      @timothy5480@timothy54803 жыл бұрын
    • @@dannygaming1216 no it's for ddos. It's mirai. All of those iptables block rules and deleting stuff is to stop other scanners running some exploits so they exclusively have the bot.

      @noobian3314@noobian33143 жыл бұрын
    • @@noobian3314 I've seen a worm that gets into the router to allow it to collect data to sell it or for blackmail and for ddos

      @dannygaming1216@dannygaming12163 жыл бұрын
  • "Please send me malware" -John Hammond

    @idoabitoftrolling2172@idoabitoftrolling21723 жыл бұрын
    • Famous last wards...

      @stevejamal241@stevejamal2413 жыл бұрын
    • "Welcome to Jurrasic Park" - John Hammond

      @Nexus4582@Nexus45823 жыл бұрын
  • 04:05 $ mkdir Mozi $ ls Listing an empty freshly created directory shows you, that you are dealing with a professional. People who don’t do this are either noobs or psychopaths.

    @Rojawa@Rojawa3 жыл бұрын
    • Agree >_

      @nashonightmare@nashonightmare3 жыл бұрын
    • Why is this?

      @chillytheprogrammer@chillytheprogrammer3 жыл бұрын
    • @@chillytheprogrammer Habits. Muscle memory. I belive John made a community post about this lol. edit: kzhead.info/tools/VeW9qkBjo3zosnqUbG7CFw.htmlcommunity?lb=UgxZplo8gPKIFaDSPVN4AaABCQ I was right :D

      @user-lk5qz4wx4q@user-lk5qz4wx4q3 жыл бұрын
    • I do this all the time. Why? I have no idea.

      @oxtna@oxtna3 жыл бұрын
    • mkdir is most tested software ever written.

      @mathiasdesouza@mathiasdesouza3 жыл бұрын
  • Cool trick “-fix-broken” That’s why I like John’s videos even when he thinks he fails. I level up ⬆️

    @matthewlandry1352@matthewlandry13523 жыл бұрын
    • Or `-f` for short!

      @okuno54@okuno543 жыл бұрын
  • somehow my evening routine of lying on the couch and watching netflix changed to lying on the couch and watching john hammond do malware analysis... :)

    @kochv87@kochv873 жыл бұрын
    • Welcome brother 😂

      @cvall1710@cvall17107 ай бұрын
  • Would love to see a mini series about setting up a honey pot and seeing what fun stuff comes through!

    @vexraill@vexraill3 жыл бұрын
    • How would one do that?

      @bannedthricelol8799@bannedthricelol87992 жыл бұрын
    • @@bannedthricelol8799 step 1: install metasploitable somewhere step 2: buy an domain for metasploitable and show it somewhere so posible hackers try to hack it step 3: profit btw metasploitable may seem sus since it has a lot of vulnerabilities up to the point where it seems fake

      @rita-the-devil@rita-the-devil2 жыл бұрын
    • @@bannedthricelol8799 just make a honey pot its that easy

      @deepergodeeper7618@deepergodeeper7618 Жыл бұрын
    • Yes!!! A malware Harvester🤩🤩🤩

      @josjuarlister1059@josjuarlister1059 Жыл бұрын
    • It's worth it... Tpot - you can do that yourself. :)

      @PiotrK2022@PiotrK2022 Жыл бұрын
  • RIP nano on the side over there, he served his purpose in his less than 5-minute life span, let's take a moment of silence to remember how he stored the file size in hex for 2 minutes and then died peacefully...

    @Zachucks@Zachucks3 жыл бұрын
    • 🤣

      @rccowboys@rccowboys Жыл бұрын
    • john killed him :((

      @tom-on@tom-on Жыл бұрын
    • Na no

      @seniorchonkza997@seniorchonkza997 Жыл бұрын
    • nano lives matter

      @swbrecordsuk@swbrecordsuk Жыл бұрын
  • 25:40 Tip: you can simulate a slower connection to see things clearer in the devtools by clicking the "Throttling" dropdown

    @pqudah@pqudah2 жыл бұрын
    • nice info

      @noviccen388@noviccen388Ай бұрын
  • Even though this is a 2 year old video I just started watching your KZhead channel a day or two or something like that but I like your content brother keep up your hard work I don't know if you do live on here or not but if you do I would love to see one of those live!!! If not keep it up I'll keep learning 😅😅 stay safe out there

    @colbyhartman9467@colbyhartman9467 Жыл бұрын
  • I see a lot of Mozi traffic requests at work. Usually targeting IoT nix systems, routers, and low hanging fruit exploits attempting to spread around.

    @97Ram1500Magnum@97Ram1500Magnum3 жыл бұрын
  • John, I love it! This is exactly what I do too. I don’t know what I’m doing but it’s fun to just scroll through to see if you see anything and sure enough you do. You also learn so much just by poking around.

    @JCtheMusicMan_@JCtheMusicMan_3 жыл бұрын
  • I stumbled across your channel a couple of days ago, and have been binge watching ever since. Great job, and impressive resume.

    @Scarter63@Scarter632 жыл бұрын
  • I just found your channel and couldn't be happier. Great energy, looking forward to digging in.

    @oijoij113@oijoij1133 жыл бұрын
  • I’m loving this series! Please do one explaining the methods you use.

    @benvoisey3942@benvoisey39423 жыл бұрын
  • For hexedit : go to start/end of the file

    @larryslobster7881@larryslobster78813 жыл бұрын
  • Even if I am barely understanding what is going on I found your videos very entertaining and educational! Thumbs up!

    @Rafalu991@Rafalu9913 жыл бұрын
  • I found your channel yesterday and have been bingewatching hardcore. Ur vids are great!

    @felkan@felkan3 жыл бұрын
  • I've discovered your channel recently and i really like it ! You are very inspiring, thank you for this amazing content !

    @John-hq9kx@John-hq9kx3 жыл бұрын
  • People: "What do you do for a living?" John: "I look at malware-strings no matter how long they are."

    @CapitanDirp@CapitanDirp Жыл бұрын
  • I have a computer science degree and can confirm I also have no idea what MIPS is.

    @makeshift27015@makeshift270153 жыл бұрын
    • its a RISC cpu by motorola. found on older systems and maybe routers

      @cryptostuff8479@cryptostuff84792 жыл бұрын
  • These videos are getting better and better ! Can't wait for what's next !

    @telnobynoyator_6183@telnobynoyator_61833 жыл бұрын
  • Love the Malware Analysis videos! And the commentary is entertaining man! Keep uploading and I'll keep watching! Thanks for the great content.

    @notmyself8800@notmyself88003 жыл бұрын
  • Really loving the Malware analysis videos. My morning routine is now watching these videos over reading a news paper 😂

    @TheAyushbest1@TheAyushbest13 жыл бұрын
  • Thank you for making these videos John!

    @JimzZel@JimzZel3 жыл бұрын
  • Thanks for your video :D They're all awesome! The strange part is that I just yesterday figured out how to cross compile code for MIPS-I for my router (it's exact the same elf type as this virus). I never heard about this architecture untill about a week ago and suddenly you upload the video with this malware intended for routers. Anyway, love the passion that you share in your videos, please keep doing it haha :D

    @olokelo@olokelo3 жыл бұрын
  • Awesome content. Thanks for putting up the video 👍🏻

    @micahweiss5832@micahweiss58323 жыл бұрын
  • "Sugar we're going down swinging, by Green Day" 😭😭😭

    @honcho1775@honcho17753 жыл бұрын
    • Me, a Fall Out Boy fan: *my disappointment is immeasurable and my day is ruined* Also Me, a John Hammond fan: I'm soooo happy there's a new video ^^

      @greniacd8396@greniacd83963 жыл бұрын
    • It made me sad too!

      @zgeekdiver@zgeekdiver3 жыл бұрын
  • I like to "customize" my UPX. Shuffle the fields of the header struct around and (binary)shift the content. XOR the compression algo by the C64 NOP and add 69 to exactly that file size shown in the video:P Also using the wrong endianess on purpose will promote hair loss. Thanks for the great video, John!:)

    @dieSpinnt@dieSpinnt3 жыл бұрын
  • Yay another one! thank you for your great work.

    @ratatta541@ratatta5413 жыл бұрын
  • Dawg this is the most entertaining shit to watch, man. I listen to you like a podcast, I could actually listen/watch you all day.

    @trapOrdoom@trapOrdoom Жыл бұрын
  • Idk why it made me laugh so hard when you dragged your cam out of the window 😂😂😂😂

    @ultimate8673@ultimate86733 жыл бұрын
  • Just came across this video and I noticed at 27:01 there is some commands for cfgtool which also sets the TR-069 (CWMP) Access Control Server to localhost, which could do a whole lot of advanced configuration/diagnostics of the device including re-flashing the firmware of the device.

    @Cazzar09@Cazzar09 Жыл бұрын
  • At 25:24 the text scanned by Google translate is: "-先进的比特币矿池" And the translation provided by it was: "-Advanced Bitcoin mining pool"

    @ScOrPiOnE905@ScOrPiOnE9052 жыл бұрын
  • Awesome, thanks for more malware content!

    @dannelson2590@dannelson25903 жыл бұрын
  • BRO THAT OUTRO MUSIC GAVE ME SOME FLASHBACKS AND NOSTALGIA

    @Omena0@Omena0 Жыл бұрын
  • appreciate you brother. keep teaching us please.

    @forhadhossain8913@forhadhossain89133 жыл бұрын
  • MIPS is usually found on routers and this is targeting routers in beginning allowing the attacker to get into the network (hence the iptables allow)

    @btnetro@btnetro3 жыл бұрын
    • Is there malware that nestles in the router before ever getting to the user machine? Would downloading it be enough for it to deploy? Or could it target the router through the VM?

      @seetheious9879@seetheious98792 жыл бұрын
  • This guy is a gem. Liking and commenting for the KZhead algorithm

    @urib101@urib1013 жыл бұрын
  • This’ll be a good one, see you all here

    @AlecArmbruster@AlecArmbruster3 жыл бұрын
  • Loving the malware analysis vids John - keep repping the blue team :)

    @stevecooper3574@stevecooper35743 жыл бұрын
  • The particular characters mean the exactly the same thing as the English title, but in Chinese. That site probably just translated it

    @user-zl6jp3sx2s@user-zl6jp3sx2s3 жыл бұрын
  • god damn so much like!! i like these break downs! they are awesome!

    @SICKFREDO@SICKFREDO3 жыл бұрын
  • @John Hammond 28:53 That highlighted command is a trick to check whether or not busybox is installed I suppose. :) Keep that in mind John that all commandss like apt etc. etc. are in fact a bin finle that is stored in /bin directory, so I think this is a instruction for DD to look inside bin folder and look for busybox folder/check for its existance. :)

    @PiotrK2022@PiotrK2022 Жыл бұрын
  • Thank you!

    @kyra371@kyra371 Жыл бұрын
  • I got a cool one at work that was a phishing attempt through a Google Drive. Instantly made me think of your deconstruction videos.

    @aaronwhite1786@aaronwhite17863 жыл бұрын
  • I think the 114 dns, that we saw, is just a normal Chinese based dns server; nothing malicious in nature about the dns itself. It could be there to add more "surface area" to the malware.

    @FreezeLuiz@FreezeLuiz3 жыл бұрын
  • This is going to be great!

    @mrikea7577@mrikea75773 жыл бұрын
  • You can kind of think of MIPS like a simpler version of ARM. It's assembly code is so much simpler compared to say ARM or x86 that my University uses it to teach assembly basics and concepts of how a processor works. In my experience it's very common in SOHO networking and IoT devices.

    @cre8ive65@cre8ive652 жыл бұрын
  • Hi John love the videos! You think you could make a tutorial on setting up a safe environment to explore malicious programs? I know virtual environments, are a start, but I think getting a video template would help put some paranoia at bay. Thanks in advance and if you already uploaded this tutorial my apologies.

    @xpz7662@xpz76623 жыл бұрын
  • Big fan John! Always loved your content!

    @stefan3816@stefan38163 жыл бұрын
  • OOOh im excited for this one

    @nathen418@nathen4183 жыл бұрын
  • I like catching these premieres. It's fun to watch, but lot's of it is over my head at this point.

    @simplepentester8476@simplepentester84763 жыл бұрын
  • John Hammond is amazing. I watch him and I dont know what he does most of the time

    @SsaliJonathan@SsaliJonathan2 жыл бұрын
  • Nice video. Can't wait for the next one! :)

    @root317@root3173 жыл бұрын
  • Good stuff, love this content man

    @TheSeakr@TheSeakr3 жыл бұрын
  • Lol he says he aint educated yet rips through anything thrown at him 🤣 😂

    @cooliceman0001@cooliceman00013 жыл бұрын
  • still new to your videos, I am thinking of starting my pentesting journey again, you may have motivated me fellow ginger

    @Thiole@Thiole3 жыл бұрын
  • I had you in the background, and as soon you mentioned netgear i was like, oh mips and netgear, he is in router infections.

    @goodiezgrigis@goodiezgrigis2 жыл бұрын
  • Thank you so much

    @orgozlan323@orgozlan3233 жыл бұрын
  • I just want to let you know that I'm screaming at you : "it's UPX packed ! why do you keep searching for string ? unpack it already !"

    @LaurentLaborde@LaurentLaborde3 жыл бұрын
  • I Think reversing Malware Is fantastic I have learned so much from watching this Ty

    @patrickgray6966@patrickgray69663 жыл бұрын
  • Destroyed and annihilated the bell! Great content!

    @rusirumunasingha2234@rusirumunasingha22343 жыл бұрын
  • Ah yes, it might be late but every hour is cyber hour.

    @witisfalse2343@witisfalse23433 жыл бұрын
  • was reading up on some botnets using Twitter formatted messages yesterday and this video now the timing confirms John get out of my computer!

    @user-nu4hr6sj9n@user-nu4hr6sj9n3 жыл бұрын
  • Thanks for the great video. I would like to be like you as a professional in virus analysis.

    @72muhamad72@72muhamad722 жыл бұрын
  • Love your energy

    @SinanAkkoyun@SinanAkkoyun3 жыл бұрын
  • 37:35 John, you have to "import file" (i) not "Open filesystem" (ctrl+i)

    @TiagoEsperancaTriques@TiagoEsperancaTriques3 жыл бұрын
    • Do you know the difference between the two? What was Ghidra trying to do with .elf with the ctrl+i option which failed? :o

      @mikekhourey521@mikekhourey5213 жыл бұрын
  • A very entertaining analysis

    @slano8850@slano88503 жыл бұрын
  • Video title: "breadcrumbs" (also a new box on hackthebox ) Me: should definitely watch this

    @thecaretaker0007@thecaretaker00073 жыл бұрын
  • Shout out from the Philippines!

    @tetetsky@tetetsky3 жыл бұрын
  • These videos are so good!!!!!

    @ItDoBeWazy@ItDoBeWazy Жыл бұрын
  • Maybe you already know that, but there is a nice Java based MIPS emulator called MARS. It is developed by the Missouri State University under the MIT license. It has some nice features like step by step execution and register editing. So if you at one point want to/need to work with MIPS, this is a great tool to assist you

    @PcFreak380@PcFreak3803 жыл бұрын
  • 0:00 John Hammond == John Hammond == John Hammond

    @TheDutchisGaming@TheDutchisGaming Жыл бұрын
  • I all-time following you sir

    @haraprasadghosh6866@haraprasadghosh68663 жыл бұрын
  • Very interesting!

    @picneec13@picneec13 Жыл бұрын
  • Love this videos!!!

    @jorgevilla6523@jorgevilla65233 жыл бұрын
  • Sees John posted another malware analysis: Likes the video. Simple as.

    @KrakenPipe@KrakenPipe3 жыл бұрын
  • 5:37 this reaction is a gold xD

    @MarcusHolloway_h3r3@MarcusHolloway_h3r3 Жыл бұрын
  • Awesome video! Keep it up!

    @kddakid6@kddakid63 жыл бұрын
  • Great video

    @blade1551431@blade15514313 жыл бұрын
  • John hammond: Please send me malware. Me: John hammond is hungry for malwares.

    @codewithsmoil4098@codewithsmoil40983 жыл бұрын
  • Bro I am completely beginner. Thanks a lot for best strings

    @kishanakbari8822@kishanakbari88223 жыл бұрын
  • Awesome!

    @diddyman1958@diddyman19583 жыл бұрын
  • John, I just thought of a Tag Line for this type of video for you. “Down the Rabbit Hole with John Hammond” 😁

    @JCtheMusicMan_@JCtheMusicMan_3 жыл бұрын
  • JOHN I WANT TO YELL AT YOU FOR ... Creating a great video 🤪

    @matthewlandry1352@matthewlandry13523 жыл бұрын
  • I hope you will continue with reversing malware 4ever

    @stefanolenocin4628@stefanolenocin46283 жыл бұрын
  • When you’re so early that john’s hearted every comment

    @originalgaming9062@originalgaming90623 жыл бұрын
  • Always here John!

    @0xRalu@0xRalu3 жыл бұрын
  • These iptables commands in the file are firewall rules (iptables is widely used on Linux) probably to open ports on your device.

    @MasthaX@MasthaX3 жыл бұрын
  • This one is doing a lot, really a lot of stuff, might even do rat, great video

    @custume@custume3 жыл бұрын
  • your videos are very entertaining and you get to learn a lot. What else is needed???

    @kharbandaumang@kharbandaumang3 жыл бұрын
  • it's nice to know how that things work ;)

    @Minecodes@Minecodes3 жыл бұрын
  • I really like this one

    @aulisarinili7297@aulisarinili72973 жыл бұрын
  • Hey John! love your content! Just a quick question. How do you CTF creators hide text in images? What tools do you use?

    @cyb3rtooth199@cyb3rtooth1993 жыл бұрын
    • There are loads of Steganography utilities, my favourite is Outguess!

      @josjuarlister1059@josjuarlister1059 Жыл бұрын
    • There's also jphide & seek and steghide, they're good ones too!

      @josjuarlister1059@josjuarlister1059 Жыл бұрын
  • I'm bummed out that Ruxcon seems to be over. Would have been cool to have met you in Oz some time John.

    @skilletpan5674@skilletpan56743 жыл бұрын
  • you and muda from someordinarygamer are so similar its crazy. love your content it is very informative and revealing.

    @zkf013@zkf0132 жыл бұрын
  • oo another malware analysis

    @slonkazoid@slonkazoid3 жыл бұрын
  • a good tool is miranda , for MIPS systems

    @justknot4481@justknot44813 жыл бұрын
  • Can't wait XD

    @roxert0@roxert03 жыл бұрын
  • Any advice for learning how to start deconstructing and creating malware, I have a decent knowledge of c++, python, but mostly Java

    @paulstone8066@paulstone80663 жыл бұрын
KZhead